VillaTheme Thank You Page Customizer for WooCommerce Broken Access Control Vulnerability

Vulnerability

A missing authorization vulnerability has been identified in the VillaTheme Thank You Page Customizer for WooCommerce – Increase Your Sales plugin, affecting versions through 1.1.7. This vulnerability arises from incorrectly configured access control, allowing unprivileged users to perform actions reserved for higher privileges.

Impact

Exploitation of this vulnerability could enable an unprivileged user to execute actions that require higher privileges, due to the lack of proper authorization checks.

Remediation

Users of the affected plugin can apply the virtual patch offered by Patchstack, which blocks attacks targeting this vulnerability until an official fix is available.

Added: Aug 14, 2025, 2:46 PM
Updated: Aug 14, 2025, 2:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
5.0
exploitability
5.4
remediation
7.9
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.